On Sun, Aug 2, 2026, at 17:51, Junrui Luo via B4 Relay wrote:
> From: Junrui Luo <[email protected]>
>
> spufs_mbox_read(), spufs_ibox_read() and spufs_wbox_write() take the
> context state_mutex with spu_acquire() and only drop it once their
> transfer loop has finished, so every put_user()/get_user() in those
> loops runs with the mutex held. The faulting address comes from
> userspace, so the fault can be made to take arbitrarily long via
> userfaultfd region or a FUSE-backed mapping.
>
> Drop the mutex around the user accesses: acquire it per mailbox element,
> just long enough for the ctx->ops mailbox operation, and release it
> before touching the user buffer.
>
> spufs_switch_log_read() has the same problem but its loop needs the lock
> for more than just the copy.
>
> Fixes: cdcc89bb1c6e ("[POWERPC] spufs: make mailbox functions handle 
> multiple elements")
> Reported-by: Yuhao Jiang <[email protected]>
> Signed-off-by: Junrui Luo <[email protected]>

I'm not sure if anything relies on the accesses to be atomic,
but it does seem unlikely, given that you typically only
have a single CPU thread interacting with an spu context.

It clearly fixes a bug, so

Reviewed-by: Arnd Bergmann <[email protected]>

      Arnd

Reply via email to